Restructuring GitHub's bug bounty program

(github.blog)

52 points | by soheilpro a day ago ago

36 comments

  • wxw 19 hours ago ago

    > We’re formalizing a permanent private/invite-only VIP program for qualified researchers who consistently deliver high-quality, high-impact work.

    > VIP program bounty table:

      Severity  Payout
      --------  --------
      Low       $1,000
      Medium    $7,500
      High      $20,000
      Critical  $30,000+
    
    > We are adjusting our public program rates to accommodate this shift in focus towards quality of relationships and findings over quantity of reports. We are also updating to static payouts—a single, clear number per severity level, rather than a wide range.

    > Our new public program bounty table:

      Severity  Payout
      --------  -------
      Low       $250
      Medium    $2,000
      High      $5,000
      Critical  $10,000
    
    
    > To reduce the volume of low-effort and AI-generated reports, we’re implementing a HackerOne signal requirement on the public program.
    • cobertos 14 hours ago ago

      > VIP program for qualified researchers who consistently deliver high-quality, high-impact work.

      Almost as though they want the quality and consistency of hired labor but not the cost

      • krystalgamer 12 hours ago ago

        it's voluntary and a nice incentive for those whose have spent time on getting familiar with the systems.

        also given that nowadays most bounty hunters have some level of automation don't see the issue of getting paid by the task instead of the by the hour. diversification of source of income is always good :)

  • dinkelberg a day ago ago

    So if the "wrong" person finds a critical vulnerability in GitHub, the payout is capped at $10,000. Might reduce the likelihood of it being submitted to the bug bounty program.

    • 21 hours ago ago
      [deleted]
    • toomuchtodo 21 hours ago ago

      It might, but as someone who has to review public vulnerability reports for a much less popular website, I completely understand why they’re building a vouch program to dissuade slop reports. One would presume their internal team is using frontier models for red team agent scanning against potential attack surface, and so this is a potential risk they’re willing to take.

      Tragedy of the commons that someone who hasn’t passed the filter yet might have their payout limited.

      Vouch - https://news.ycombinator.com/item?id=46930961 - February 2026 (486 comments)

      • tancop 11 hours ago ago

        vouch programs where other users put their trust in you are a good thing. this is a centralized vip program where membership can be added or removed from anyone for no reason. there is no guaranteed way to get in. its a private club not a trust system.

      • super256 21 hours ago ago

        tbh hackerone should just implement a +/- reputation points feature on researcher profiles. Like, the researcher submits a slop report to GitHub via H1, GitHub looks at it and identifies it as slop, GitHub presses the -rep button on reaearcher profile which bans them from submitting to GitHub on H1 again and makes their rep points minus 1. Companies should be able to configure you need at least 10 rep points to receive payouts. Only specific (by H1 chosen) companies can +/- rep.

        So, researchers first need to collect some positive rep. But the rep points are global, so once you have fixed a few bugs for Google, you've gotten enough +rep that you can also receive stuff at GitHub.

        Oh, and ID check when signing up at H1.

        Long term all beg bounty submitters would be banned for pretty much all of tech.

        • Synthetic7346 18 hours ago ago

          I think they do that already, there are signal ratios

        • ofjcihen 12 hours ago ago

          Signal and Reputation already do these things but public programs are…well public.

      • account42 12 hours ago ago

        You're forgetting that GitHub aka Microsoft is one of the big slop peddlers. They made the problem but now don't want to pay for it.

        • inigyou 12 hours ago ago

          "one of the big" is an understatement. They own OpenAI, which created and popularized the whole field.

        • toomuchtodo 12 hours ago ago

          Large organizations are complex machines. The security team responsible for triaging these reports is very likely not the same as the one peddling slop. The nuance and irony is not lost on me.

      • applfanboysbgon 20 hours ago ago

        How does decreasing pay for humans discourage slop reports, exactly?

        • dfedbeef 20 hours ago ago

          It discourages all reports, so you get the reduced slop reports for free.

          • sevenseacat 15 hours ago ago

            To my mind, it encourages more reports because that way you're more likely to have some of them slip through and get approved, meaning your future reports are worth more.

          • applfanboysbgon 19 hours ago ago

            Does it, though? It discourages humans from putting in effort because their time will not be rewarded. But the slop reports were not the result of time nor effort. I'd rather expect changing a payout from $1k to $250 doesn't meaningfully move the needle on someone spending two minutes prompting their OpenClaw to spam bug bounties. Especially since the reports you actually want to filter out are the sub-50-IQ reports that were always going to get $0 either way.

    • greatgib 13 hours ago ago

      I find it quite offensive that there is a payout difference for major vulnerabilities when the outcome is the end in the end.

      If it was me finding such a vulnerability, this discrimination would offend me so much that I would prefer to sell it to semi-legal actors that would pay multiple of that...

  • everfrustrated 13 hours ago ago

    Seems to me like the game theory here is un-credentialed reporters need to submit their reports through credentialed folks who will vet and take a cut on the way through.

    Why take the lower offer by going directly.

    That sounds like a win for everyone involved.

    • htrp 11 hours ago ago

      still removing work from github.

      this is formalizing some very enterprise-esque processes for security research, software resellers anyone?

  • saagarjha 20 hours ago ago

    I wonder if this incentivizes people to form groups that self-vet for quality submissions to enhance their reputation.

    • w0m 11 hours ago ago

      i mean; that sounds like a win for GH right?

  • darkamaul 19 hours ago ago

    I believe the changes here make a lot of sense because, most of the time, your best bugs are not your first ones

    Anyone can point an LLM to a code base and ask to find a vulnerability - and the initial set of findings is going to be rather lame.

    Encouraging researchers to stick to a target and to report 7 lows before getting in will probably make their contributions more valuable.

  • Klaster_1 21 hours ago ago
  • poly2it 16 hours ago ago

    Does this reflect new pricing in the black (hat) market?

  • Schnitz 19 hours ago ago

    It is much harder to refute bullshit than to make up bullshit. As harsh or unfair as it might seem, this makes sense.

  • sdevonoes 15 hours ago ago

    Another reason why LLMs suck. So far cons > pros

    • embedding-shape 14 hours ago ago

      > So far cons > pros

      Lets say 80% of the world's population decides the cons outweight the pros, now what? Put the genie back in the bottle, something that is famously easy and trivial to do?

      • account42 12 hours ago ago

        If the will was there we could shut down commercial providers tomorrow, which would already solve most of the problem.

        • embedding-shape 12 hours ago ago

          Alright, so assuming thats done now, obviously everyone moves to local models. Would the suggestion be to outlaw those too, and if so, what would the enforcement look like?

    • frizlab 14 hours ago ago

      Most definitely, yeah.

  • applfanboysbgon 20 hours ago ago

    I mean, this is just a "fuck you", right? "Because there's a lot of LLM spam, we've decided that some researchers will get 1/4th as much pay for reporting the same bug as others, even if they didn't use LLMs". If anything this will have the opposite of the intended effect -- this strongly discourages humans who aren't part of the VIP program from reporting bugs they find to Github, so you'll probably see a higher ratio of LLM spam in the future. And don't be surprised if those bugs get sold elsewhere...

  • nullsanity 18 hours ago ago

    [dead]

  • fragmede 20 hours ago ago

    [flagged]

    • 2001zhaozhao 18 hours ago ago

      They seem to be doing this to disincentive people who spam bug reports with AI where only 10% of them are actually real.

      Instead, now you probably need to be actually vetting your bug reports yourself so that a large percentage of them are real, before they let you in the verified program, where you get a normal amount of payout.

      So it incentivizes high quality AI bug spamming (if you can manage it) over low quality AI bug spamming. In turn since less people are doing low quality AI bug spamming, Github gets to spend less time filtering the low quality reports.

    • jonoc 19 hours ago ago

      I get the joke, but I don’t think GitHub is treating one type of person as inherently more deserving. They’re paying for signal and reduced triage cost as well as the vulnerability itself. AI makes it incredibly cheap to flood them with plausible-looking false positives, while their investigation capacity is finite.